Impact
BharatMLStack versions 1.3.0 and earlier embed user‑supplied content directly in the Trufflebox UI component, ExpressionViewModal.jsx, without proper sanitization. This flaw allows arbitrary scripts to be injected and executed in the browser context of any user who opens the modal, constituting a classic cross‑site scripting weakness.
Affected Systems
Affecting BharatMLStack up to and including version 1.3.0. No other vendors or products are listed in the CNA data. Users running the vulnerable versions are considered exposed.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity; the EPSS score of less than 1% shows a very low but nonzero likelihood of exploitation; the vulnerability is not listed in the CISA KEV catalog. Attackers would supply malicious content that is rendered within the ExpressionViewModal, resulting in script execution in the victim’s browser context.
OpenCVE Enrichment